Thanks Scott,

I just got finished reviewing data in the Google-verse and found the content 
you are referencing. It’s nice to have confirmation I was getting reliable hits.

In summary it seems the text that is now in 4.10 is indeed optional.

What is also frustrating is the guidance info in A.4.10 refers to “the 
assessment requirement” – which is not a statement of fact, there is no 
assessment requirement.

Best Regards,
-Lauren



Confidential – Limited Access and Use
From: Scott Aldous <[email protected]>
Sent: Friday, August 23, 2024 4:45 PM
To: [email protected]
Subject: Re: [PSES] NFPA cybersecurity "shall be permitted"?

You don't often get email from 
[email protected]<mailto:[email protected]>.
 Learn why this is important<https://aka.ms/LearnAboutSenderIdentification>



External Email: Do NOT reply, click on links, or open attachments unless you 
recognize the sender and know the content is safe. If you believe this email 
may be unsafe, please click on the “Report Phishing” button on the top right of 
Outlook.


Hi Lauren,

Digging a bit, it looks like this was originally proposed as a hard 
requirement. See PI 22 in this 
doc<https://docinfofiles.nfpa.org/files/AboutTheCodes/79/79_F2023_EEI_AAA_FD_PIResponses.pdf>
 (you can search on "cybersecurity" to find it). This was proposed by Keith 
Waters from Schneider Electric, and at the time included "shall" rather than 
"shall be permitted".The committee statement was that "the proposed language is 
overly broad and restrictive."

If you search on "cybersecurity" in this 
doc<https://docinfofiles.nfpa.org/files/AboutTheCodes/79/79_F2023_EEI_AAA_SD_PCResponses.pdf>,
 you can find a subsequent public comment where the same submitter revised the 
proposal, this time modifying the language that would have made it mandatory. 
The submitter's comment there states:

"In reviewing the response to the original PI, I still feel that cybersecurity 
is essential to properly protecting industrial machinery and a consensus 
standard is the best way to protect these systems in lieu of 51 different 
requirements from the federal government and the individual states. However, I 
understand that we need to create a starting point to learn the best methods 
before setting full requirements. The change to the PI to make the requirement 
“shall be permitted” vs “shall” is a good first step into creating the safety 
and reliability protections."

Even though this second comment was rejected, it references a subsequent 
revision with much the same language that can be found 
here<https://docinfofiles.nfpa.org/files/AboutTheCodes/79/79_F2023_EEI_AAA_SD_SRStatements.pdf>.

On Fri, Aug 23, 2024 at 2:20 PM Ralph McDiarmid 
<[email protected]<mailto:[email protected]>> wrote:
Sounds optional to me too.  You’re allowed to do it, but you’re not required to 
do it.

It’s Friday in Canada and Mexico too, but the way    ;>)


Ralph


From: Lauren Crane 
<[email protected]<mailto:[email protected]>>
Sent: Friday, August 23, 2024 1:34 PM
To: [email protected]<mailto:[email protected]>
Subject: [PSES] NFPA cybersecurity "shall be permitted"?

Hello All,

Happy Friday (US)….

There is a new section in NFPA 79 - 2024 edition – “4.10 Cybersecurity.  
Industrial machinery that is connected to a communication network and permitted 
to control any part of the machinery shall be permitted to comply with the 
following: (1) A cybersecurity assessment conducted on the connected system to 
determine vulnerabilities to cyberattacks; (2) A cybersecurity commissioning 
certification conducted on the connected system to ensure it is designed 
against cyberattacks and known vulnerabilities; (3) Documentation of the 
assessment and certification provided to those authorized to inspect, operate, 
and maintain the system”

My best take at this is the whole thing is optional given the underlined “shall 
be permitted”. That phrase seems to mean (as it is used throughout NFPA 79) “is 
allowed”.  But if I read it that way, it means the whole section 4.10 was added 
just to say one is allowed to do 3 things and it has no obligation to actually 
do anything, which seems off - because it is rather silly – Particularly since 
doing what is listed would not reasonably be questioned, so it doesn’t really 
need to be clarified that one is allowed to do it.

Do any of you have a different take on this?

Best Regards,
-Lauren


LAM RESEARCH CONFIDENTIALITY NOTICE: This e-mail transmission, and any 
documents, files, or previous e-mail messages attached to it, (collectively, 
"E-mail Transmission") may be subject to one or more of the following based on 
the associated sensitivity level: E-mail Transmission (i) contains confidential 
information, (ii) is prohibited from distribution outside of Lam, and/or (iii) 
is intended solely for and restricted to the specified recipient(s). If you are 
not the intended recipient, or a person responsible for delivering it to the 
intended recipient, you are hereby notified that any disclosure, copying, 
distribution or use of any of the information contained in or attached to this 
message is STRICTLY PROHIBITED. If you have received this transmission in 
error, please immediately notify the sender and destroy the original 
transmission and its attachments without reading them or saving them to disk. 
Thank you.


Confidential – Limited Access and Use

________________________________

This message is from the IEEE Product Safety Engineering Society emc-pstc 
discussion list. To post a message to the list, send your e-mail to 
[email protected]<mailto:[email protected]>
All emc-pstc postings are archived and searchable on the web at:
https://www.mail-archive.com/[email protected]/<https://www.mail-archive.com/[email protected]/%20>

Website: https://ewh.ieee.org/soc/pses/
Instructions: https://ewh.ieee.org/soc/pses/list.html (including how to 
unsubscribe)<https://ewh.ieee.org/soc/pses/list.html>
List rules: https://ewh.ieee.org/soc/pses/listrules.html

For help, send mail to the list administrators:
Mike Sherman at: [email protected]<mailto:[email protected]>
Rick Linford at: [email protected]<mailto:[email protected]>

For policy questions, send mail to:
Jim Bacher at: [email protected]<mailto:[email protected]>

________________________________

To unsubscribe from the EMC-PSTC list, click the following link: 
https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1

________________________________

This message is from the IEEE Product Safety Engineering Society emc-pstc 
discussion list. To post a message to the list, send your e-mail to 
[email protected]<mailto:[email protected]>
All emc-pstc postings are archived and searchable on the web at:
https://www.mail-archive.com/[email protected]/

Website: https://ewh.ieee.org/soc/pses/
Instructions: https://ewh.ieee.org/soc/pses/list.html (including how to 
unsubscribe)<https://ewh.ieee.org/soc/pses/list.html>
List rules: https://ewh.ieee.org/soc/pses/listrules.html

For help, send mail to the list administrators:
Mike Sherman at: [email protected]<mailto:[email protected]>
Rick Linford at: [email protected]<mailto:[email protected]>

For policy questions, send mail to:
Jim Bacher at: [email protected]<mailto:[email protected]>

________________________________

To unsubscribe from the EMC-PSTC list, click the following link: 
https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1


--
Scott Aldous | Regulatory Compliance Manager | 
[email protected]<mailto:[email protected]> | 650-253-1994

________________________________

This message is from the IEEE Product Safety Engineering Society emc-pstc 
discussion list. To post a message to the list, send your e-mail to 
[email protected]<mailto:[email protected]>
All emc-pstc postings are archived and searchable on the web at:
https://www.mail-archive.com/[email protected]/

Website: https://ewh.ieee.org/soc/pses/
Instructions: https://ewh.ieee.org/soc/pses/list.html (including how to 
unsubscribe)<https://ewh.ieee.org/soc/pses/list.html>
List rules: https://ewh.ieee.org/soc/pses/listrules.html

For help, send mail to the list administrators:
Mike Sherman at: [email protected]<mailto:[email protected]>
Rick Linford at: [email protected]<mailto:[email protected]>

For policy questions, send mail to:
Jim Bacher at: [email protected]<mailto:[email protected]>

________________________________

To unsubscribe from the EMC-PSTC list, click the following link: 
https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1

-
----------------------------------------------------------------
This message is from the IEEE Product Safety Engineering Society emc-pstc 
discussion list. To post a message to the list, send your e-mail to 
[email protected]

All emc-pstc postings are archived and searchable on the web at:
https://www.mail-archive.com/[email protected]/

Website:  https://ewh.ieee.org/soc/pses/
Instructions:  https://ewh.ieee.org/soc/pses/list.html (including how to 
unsubscribe)
List rules: https://ewh.ieee.org/soc/pses/listrules.html

For help, send mail to the list administrators:
Mike Sherman at: [email protected]
Rick Linford at: [email protected]

For policy questions, send mail to:
Jim Bacher:  <[email protected]>
_________________________________________________
To unsubscribe from the EMC-PSTC list, click the following link: 
https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1

Reply via email to